Executive brief
Windows Remote Access Connection Manager is a system service that manages remote access connections on Windows machines. A use-after-free vulnerability in this service allows an authorized local user to execute code with elevated privileges, potentially leading to full system compromise.
Technical details
A use-after-free vulnerability exists in Windows Remote Access Connection Manager where freed memory is accessed after deallocation. An authorized attacker with local access can trigger this memory safety flaw to achieve privilege escalation. The vulnerability requires local access and existing privileges on the system. Successful exploitation allows an attacker to execute arbitrary code in the context of the Remote Access Connection Manager service, which runs with elevated privileges.
Affected products
- Microsoft Windows Remote Access Connection Manager
Timeline
- 2026-09-08: disclosed